2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23292MEDIUM4.6NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Atta...
CVE-2025-56520MEDIUM5.3Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_...
CVE-2025-56207MEDIUM6.5A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Et...
CVE-2025-56676MEDIUM5.4TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary p...
CVE-2025-56018MEDIUM6.1SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category...
CVE-2025-55797MEDIUM6.5An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauth...
CVE-2025-54477MEDIUM5.3Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
CVE-2025-54476MEDIUM4.8Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.
CVE-2025-57852MEDIUM6.4A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas...
CVE-2025-28016MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Re...
CVE-2025-9232MEDIUM5.9Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p...
CVE-2025-9231MEDIUM6.5Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 ...
CVE-2025-52050MEDIUM6.5In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_pr...
CVE-2025-52049MEDIUM6.5In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py ...
CVE-2025-52047MEDIUM6.5In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Inj...
CVE-2025-52043MEDIUM6.5In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_ac...
CVE-2025-10859MEDIUM4Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info...
CVE-2025-10217MEDIUM6A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log dat...
CVE-2025-9948MEDIUM4.3The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-9946MEDIUM6.1The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2025-9852MEDIUM6.4The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-...
CVE-2025-8777MEDIUM6.4The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all ver...
CVE-2025-8624MEDIUM6.4The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in...
CVE-2025-8623MEDIUM6.4The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm...
CVE-2025-8608MEDIUM6.4The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now